SQL Injection Vulnerability in Cisco Prime Infrastructure and EPNM
CVE-2025-20272

4.3MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20272?

A vulnerability exists in the REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager, which allows authenticated, low-privileged remote attackers to perform blind SQL injection attacks. This issue arises from inadequate validation of user-supplied input, enabling attackers to manipulate requests sent to the affected APIs. If successfully exploited, this vulnerability could grant access to sensitive data contained within specific database tables on the compromised device.

Affected Version(s)

Cisco Evolved Programmable Network Manager (EPNM) 3.0.1

Cisco Evolved Programmable Network Manager (EPNM) 3.1.2

Cisco Evolved Programmable Network Manager (EPNM) 1.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20272 : SQL Injection Vulnerability in Cisco Prime Infrastructure and EPNM